CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_top.php and (2) admin/includes/application_top.php.
References
Link | Resource |
---|---|
http://hosting-4-creloaded.com/node/116 | Exploit |
Configurations
Configuration 1 (hide)
|
Information
Published : 2011-06-08 08:55
Updated : 2012-04-24 21:00
NVD link : CVE-2009-5077
Mitre link : CVE-2009-5077
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
creloaded
- cre_loaded